This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies.  > Find out more here

 

All the latest UK technology news, reviews and analysis

HTC patches Wi-Fi vulnerability in its smartphones

by Chris Martin

03 Feb 2012

View Comments

  • Tweet this
The HTC Sensation smartphone

HTC has provided a firmware update to fix a "small" security hole which allowed Wi-Fi credentials to be easily stolen.

Security researchers at Open1X outlined the flaw, which they rated as critical. They revealed that HTC and Google were informed of the problem last September.

"There is an issue in certain HTC builds of Android that can expose the user's 802.1X Wi-Fi credentials to any program with basic Wi-Fi permissions," said Chris Hessing and Bret Jordan, security architects at Open1X. 

"When this is paired with the internet access permissions, which most applications have, an application could easily send all stored Wi-Fi network credentials (user names, passwords, and SSID information) to a remote server."

HTC said it had developed a fix for the issue.

"Most phones have received this fix already through regular updates and upgrades. However, some phones will need to have the fix manually loaded."

Affected devices are the Desire HD, Glacier, Droid Incredible, Thunderbolt 4G, Sensation, Sensation 4G, Desire S, Evo 3D and Evo 4D.

Despite the big time lapse between the discovery of the issue and HTC releasing a fix, Hessing and Jordan commended the two firms' handling of the problem.

"Google and HTC have been very responsive and good to work with on this issue. Google has made changes to the Android code to help better protect the credential store and HTC has released updates for all currently supported phones and side-loads for all non-supported phones," they said.

Do you agree

blog comments powered by Disqus

Poll

Business security poll

How concerned are you by the rising tide of cyber threats?

16%

55%

10%

10%

9%

Popular Threads

Powered by Disqus
BlackBerry Q5

BlackBerry Q5 video demo

BlackBerry's latest smartphone is a mid-tier handset that will cost less than the Q10 and Z10

Updating your subscription status Loading

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

newsletter sign-up button

mcafee

7 requirements for hybrid web delivery

It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model

navisite

BYOD: the implications for the IT team

BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs

Project Manager - OMS - Trading Systems

Project Manager - OMS - Trading Systems Project Manager...

C# Software Developer - ASP.NET

Software Developer ( ASP.NET C# ) Urgently needed...

Web Applications Developer

Web / .NET Developer ( ASP.NET, VB.NET, HTML, CSS, SQL...

Software Tester - Black / White Box

Tester / Software Tester / QA Analyst ( Black & White...

To send to more than one email address, simply separate each address with a comma.